Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-9076

Опубликовано: 15 сент. 2025
Источник: debian
EPSS Низкий

Описание

Mattermost versions 10.10.x <= 10.10.1 fail to properly sanitize user data during shared channel membership synchronization, which allows malicious or compromised remote clusters to access sensitive user information via unsanitized user objects. This vulnerability affects Mattermost Server instances with shared channels enabled.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
mattermost-serveritppackage

EPSS

Процентиль: 17%
0.0026
Низкий

Связанные уязвимости

CVSS3: 6.5
nvd
12 месяцев назад

Mattermost versions 10.10.x <= 10.10.1 fail to properly sanitize user data during shared channel membership synchronization, which allows malicious or compromised remote clusters to access sensitive user information via unsanitized user objects. This vulnerability affects Mattermost Server instances with shared channels enabled.

CVSS3: 6.5
github
12 месяцев назад

Mattermost Missing Authorization vulnerability

EPSS

Процентиль: 17%
0.0026
Низкий